Frameworks

What is HIPAA?

HIPAA is a US law that sets national standards for protecting health information. Its Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI), and its Breach Notification Rule governs what happens after a breach.

Definition

HIPAA (the Health Insurance Portability and Accountability Act of 1996) is a US federal law. For security and privacy purposes, it sets standards for how protected health information (PHI) must be safeguarded by covered entities and their business associates.

Background

HIPAA is enforced by the US Department of Health and Human Services. Three rules matter most for a security program: the Privacy Rule (how PHI may be used and disclosed), the Security Rule (administrative, physical, and technical safeguards for electronic PHI), and the Breach Notification Rule (notifying individuals and regulators after a breach). A covered entity is a healthcare provider, health plan, or clearinghouse; a business associate is a vendor that handles PHI on their behalf, bound by a Business Associate Agreement (BAA).

Why it matters

If your product touches health data on behalf of a covered entity, you are almost certainly a business associate and directly liable under HIPAA. Buyers will require a signed BAA and evidence of a real security program before they share PHI with you.

Step by step

  1. Determine your role: covered entity or business associate, and where PHI flows.
  2. Run a HIPAA Security Rule risk analysis.
  3. Implement administrative, physical, and technical safeguards (access controls, encryption, audit logging, workforce training).
  4. Sign Business Associate Agreements with every vendor that touches PHI, and with your customers where you are the business associate.
  5. Stand up breach detection and a documented breach-notification process.
  6. Review and update the program as systems and vendors change.

Examples

  • A telehealth startup is a business associate to the clinics it serves, so it signs BAAs and encrypts ePHI in transit and at rest.
  • A billing SaaS restricts PHI access to the minimum necessary and logs every access for its audit trail.

Common mistakes

  • Assuming HIPAA has a certification: there is no official HIPAA certificate, only demonstrable compliance.
  • Forgetting BAAs with downstream vendors that also touch PHI.
  • Skipping the required risk analysis, which is the most-cited failing in enforcement actions.

FAQ

Is there a HIPAA certification?

No. HIPAA compliance is demonstrated through your safeguards, documentation, risk analysis, and agreements. Third-party assessments can attest to your program, but they are not an official government certificate.

What is the difference between PHI and ePHI?

PHI is protected health information in any form; ePHI is PHI created, stored, or transmitted electronically. The Security Rule specifically governs ePHI.

What is a Business Associate Agreement?

A BAA is a contract that binds a vendor handling PHI to HIPAA’s requirements. Covered entities must have one with each business associate, and business associates must have them with their subcontractors.

Related

HIPAA in Keel → What is vendor risk management? → What is SOC 2? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free